Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-28168 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
network
high complexity
axios siemens CWE-918
5.9
2020-10-22 CVE-2018-18508 NULL Pointer Dereference vulnerability in multiple products
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
network
low complexity
mozilla siemens CWE-476
6.5
2020-10-15 CVE-2020-15794 Information Exposure Through an Error Message vulnerability in Siemens Desigo Insight 4.0/5.0/6.0
A vulnerability has been identified in Desigo Insight (All versions).
network
low complexity
siemens CWE-209
4.3
2020-10-15 CVE-2020-15793 Unspecified vulnerability in Siemens Desigo Insight 4.0/5.0/6.0
A vulnerability has been identified in Desigo Insight (All versions).
network
low complexity
siemens
5.4
2020-10-15 CVE-2020-15792 Unspecified vulnerability in Siemens Desigo Insight 4.0/5.0/6.0
A vulnerability has been identified in Desigo Insight (All versions).
network
low complexity
siemens
4.3
2020-10-13 CVE-2020-15797 Unspecified vulnerability in Siemens DCA Vantage Analyzer Firmware
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590.
low complexity
siemens
6.8
2020-10-13 CVE-2020-7590 Unspecified vulnerability in Siemens DCA Vantage Analyzer Firmware
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590.
low complexity
siemens
6.8
2020-09-09 CVE-2020-15791 Unspecified vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl.
low complexity
siemens
6.5
2020-09-09 CVE-2020-15790 Information Exposure vulnerability in Siemens Spectrum Power 4 4.70
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8).
network
low complexity
siemens CWE-200
5.3
2020-09-09 CVE-2020-15788 Cross-site Scripting vulnerability in Siemens Polarion Subversion Webclient
A vulnerability has been identified in Polarion Subversion Webclient (All versions).
network
low complexity
siemens CWE-79
6.1